Ãë¾àÁ¡ID |
22222 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Plug and Play À¥ ¼¹ö´Â dot dot ½ÃÄö½º¸¦ ÅëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Plug and Play À¥ ¼¹ö´Â Windows Ç÷§Æû »ó¿¡¼ À¥ »çÀÌÆ®¸¦ ±¸ÃàÇϱâ À§ÇÑ ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁöÀÌ´Ù. ÀÌ À¥ ¼¹öÀÇ 1.0002c ¹öÀü¿¡´Â '../' ¶Ç´Â '..\' ½ÃÄö½º¸¦ »ç¿ëÇÏ¿© ¼¹öÀÇ ·çÆ® µð·ºÅ丮 ¿ÜºÎ¸¦ Ž»öÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ À¥ ¼¹ö¿¡ '../' ¶Ç´Â '..\' ½ÃÄö½º¸¦ »ç¿ëÇÏ¿© Àß Á¶ÀÛµÈ URL ¿äûÀ» Àü´ÞÇÔÀ¸·Î½á, ´ë»ó ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» Àоî¿Ã ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇϸé Áß¿äÇÑ Á¤º¸¸¦ ȹµæÇÒ ¼ö ÀÖÀ¸¸ç, ȹµæµÈ Á¤º¸µéÀº ´ë»ó ½Ã½ºÅÛ¿¡ º¸´Ù Áö´ÉÀûÀÎ °ø°ÝÀ» ¼öÇàÇϱâ À§ÇØ À¯¿ëÇÏ°Ô »ç¿ëµÉ ¼ö ÀÖ´Ù.
http://[target_server]/../../windows/win.ini
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/338090
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Plug and Play Web Server 1.0 002c |
ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
8645 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|